Privacy Preserving Attestation Using Zero-Knowledge Proofs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Maintaining the security and privacy of virtual computing environments in third-party computing resource service providers is complex, as verifying the trustworthiness and integrity of these environments can reveal sensitive information about the provider's infrastructure, making it difficult to protect against malicious entities.

Innovation Solution

A computer-implemented attestation process that generates a proof of attestation data without revealing private or sensitive information, using a trusted platform module (TPM) to validate the host's configuration and integrity, and a zero-knowledge proof system to confirm the validity of the attestation data without disclosing sensitive details.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If verification of computing environment integrity is performed, then security and trustworthiness are improved, but sensitive information about the provider's infrastructure is revealed

Engineering Contradiction:
ImprovesecurityVSAvoidprivacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts only the necessary verification information from the computing environment while leaving sensitive infrastructure details hidden. The attestation process selectively outputs integrity verification data without exposing provider-specific configuration details, thereby achieving security verification while preserving privacy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary attestation process that acts as a mediator between the computing environment verification and the customer. This intermediary validates the environment's integrity through cryptographic proofs without directly exposing sensitive infrastructure information, resolving the contradiction between verification and privacy protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If detailed monitoring of computing environments is implemented, then security verification is improved, but resource consumption increases

Engineering Contradiction:
Improvesecurity verificationVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The computing environment performs self-verification through automated attestation processes. The environment generates its own cryptographic proofs of integrity without requiring external monitoring resources, thereby improving security verification while minimizing additional resource consumption. The system serves its own verification needs internally.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces traditional mechanical monitoring approaches with cryptographic verification mechanisms. Instead of continuous resource-intensive monitoring of computing environments, the system uses mathematical proofs and digital signatures to verify integrity, dramatically reducing resource consumption while maintaining or improving verification reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12132844B1Privacy preserving attestation
Publication Date: 2024.10.29 AMAZON TECH INC
  • US12132844B1 patent drawing
  • US12132844B1 patent drawing
  • US12132844B1 patent drawing

AI summary

Described implementations obtain a proof of valid attestation data. The attestation data may include configuration data of a host computing system. A prover service may receive the attestation data. The prover service may generate a proof to prove that the attestation data includes valid configuration data of the host computer system, without revealing sensitive or private information of the host computing system. The proof may be a zero-knowledge proof.